Vetting Browser Extensions for Security Vulnerabilities with VEX.
The browser has become the de facto platform for everyday computation and a popular target for attackers of computer systems. Among the many potential attacks that target or exploit browsers, vulnerabilities in browser extensions have received relatively little attention. Currently, extensions are v...
| Publicado en: | Communications of the ACM Vol. 54; no. 9; pp. 91 - 100 |
|---|---|
| Autores principales: | , , , , , |
| Formato: | Artículo |
| Publicado: |
Association for Computing Machinery
Sep2011
|
| Materias: | |
| Acceso en línea: | Ver este registro en EBSCOhost |
| fields | @attributes: recordID: 1 pdfLink: plink: https://search.ebscohost.com/login.aspx?direct=true&db=hlh&AN=67134753&site=ehost-live header: @attributes: shortDbName: hlh uiTerm: 67134753 longDbName: Humanities International Complete uiTag: AN controlInfo: bkinfo: jinfo: jid: 00010782 ACM jtl: Communications of the ACM issn: 00010782 maglogo: N pubinfo: dt: Sep2011 vid: 54 iid: 9 pid: 68 pub: Association for Computing Machinery artinfo: ui: 67134753 10.1145/1995376.1995398 ppf: 91 ppct: 9 formats: tig: atl: Vetting Browser Extensions for Security Vulnerabilities with VEX. aug: au: Bandhakavi, Sruthi Tiku, Nandit Pittman, Wyatt King, Samuel T. Madhusudan, P. Winslett, Marianne affil: Department of Computer Science, University of Illinois at Urbana, Champaign su: Web browser security Anti-malware (Computer software) Malware Computer security JavaScript programming language World Wide Web sug: subj: Web browser security Anti-malware (Computer software) Malware Computer security JavaScript programming language World Wide Web ab: The browser has become the de facto platform for everyday computation and a popular target for attackers of computer systems. Among the many potential attacks that target or exploit browsers, vulnerabilities in browser extensions have received relatively little attention. Currently, extensions are vetted by manual inspection, which is time consuming and subject to human error. In this paper, we present Vex, a framework for applying static information flow analysis to JavaScript code to identify security vulnerabilities in browser extensions. We describe several patterns of flows that can lead to privilege escalations in Firefox extensions. Vex analyzes Firefox extensions for such flow patterns using high-precision, context-sensitive, flow-sensitive static analysis. We subject 2460 browser extensions to the analysis, and Vex finds 5 of the 18 previously known vulnerabilities and 7 previously unknown vulnerabilities. pubtype: Periodical doctype: Article src: R language: English refInfo: copyright: @attributes: flag: Y dt: @attributes: year: 2011 holdings: @attributes: islocal: N |
|---|